PT-2026-95234 · WordPress · Qi Addons For Elementor

CVE-2026-84902

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions King Addons for Elementor versions prior to 51.1.81
Description An issue exists where the software fails to perform an object-level authorization check during the import of template content into a page. This allows users with contributor-level access or higher to overwrite the content of arbitrary posts and pages, including those belonging to administrators. Additionally, JavaScript can be injected via a widget setting that is output without escaping, leading to Stored Cross-Site Scripting (XSS), which is a vulnerability that allows an attacker to store malicious scripts on a server that are then executed in the browser of any user viewing the affected page.
Recommendations Update to version 51.1.81 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84902

Affected Products

Qi Addons For Elementor